PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88994 All Bootstrap Blocks CVE debrief

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached.

Vendor
All Bootstrap Blocks
Product
All Bootstrap Blocks
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-18
Original CVE updated
2026-09-18
Advisory published
2026-09-18
Advisory updated
2026-09-18

Who should care

WordPress administrators, security teams, and developers using the All Bootstrap Blocks plugin should assess exposure and prioritize remediation to prevent arbitrary file inclusion and execution.

Why it matters

This vulnerability allows users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP code. WordPress administrators and security teams should assess exposure and prioritize remediation to prevent potential security breaches.

  • Arbitrary local file inclusion and disclosure of file contents
  • Execution of PHP code where a local file containing PHP code can be reached
  • Potential for privilege escalation through exploitation of vulnerable plugin

Technical summary

The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file containing PHP code can be reached. Exploitation requires the plugin's Lightspeed subsystem to be enabled.

Defensive priority

Assess exposure and prioritize remediation for WordPress installations using the All Bootstrap Blocks plugin, especially those with contributor-level access or higher.

Recommended defensive actions

  • Assess exposure by checking if the All Bootstrap Blocks plugin is installed and enabled on WordPress installations
  • Verify if the Lightspeed subsystem is enabled, as exploitation requires this feature
  • Restrict contributor-level access and above to prevent arbitrary file inclusion and execution
  • Consider updating the plugin to a version that addresses this vulnerability, if available
  • Perform a thorough review of system logs to detect potential exploitation attempts
  • Implement additional monitoring for unusual file access or execution patterns
  • Document and track remediation efforts for auditing and compliance purposes

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources may be necessary to fully understand the impact and mitigation strategies.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88994 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88994

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88994 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88994

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.